osloadw8.exe

OS Loader

SLI

Publisher:
Microsoft Corporation  (signed by SLI)

Product:
Microsoft® Windows® Operating System

Description:
OS Loader

Version:
6.3.9600.16384 (winblue_rtm.130821-1623)

MD5:
8a5337d56cbebfb48094ecab070d68ea

SHA-1:
cc3f7583f42d0e1ea197c6702d9b193aa62522cb

SHA-256:
132f9505bc2bec82ce47636e493e417e773882e357110dbc1d92f498ca6669ed

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/25/2024 1:31:39 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W64.HfsAutoB
1.3.0.4959

File size:
1.4 MB (1,515,504 bytes)

Product version:
6.3.9600.16384

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
osloader.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\wloaders\x64\osloadw8.exe

Digital Signature
Signed by:

Authority:
SLI

Valid from:
7/31/2011 7:52:10 AM

Valid to:
12/31/2039 11:59:59 PM

Subject:
CN=SLI

Issuer:
CN=SLI

Serial number:
B6D73A057CC856B648BA07BC372E9934

File PE Metadata
Compilation timestamp:
8/22/2013 12:41:42 PM

OS bitness:
Win64

Subsystem:

Linker version:
11.0

CTPH (ssdeep):
24576:syYD85xbVILy7FRX7POY7Kva3sgThBmQMS5xWMOTh1GwPmGdqVBQVQBN1:zvVwyXX7POJvAThBmQx5x5OFPmoVu

Entry address:
0x61C0

Entry point:
48, 89, 5C, 24, 18, 48, 89, 7C, 24, 20, 55, 48, 8B, EC, 48, 81, EC, 80, 00, 00, 00, 8B, 59, 34, 48, 83, 65, C8, 00, 83, 65, E0, 00, 83, 65, F0, 00, 48, 83, 65, B8, 00, 41, B8, 00, 04, 00, 00, 44, 89, 45, D8, 48, 03, D9, C7, 45, D0, 14, 00, 00, 00, C7, 45, D4, 01, 00, 00, 00, 48, 8B, 45, D0, C7, 45, DC, 00, 00, 20, 00, 48, 89, 45, A0, 48, 8B, 45, D8, 48, 8D, 55, A0, 48, 89, 45, A8, 48, 8B, 45, E0, C7, 03, 01, 00, 00, 00, 48, 89, 45, B0, 48, 8B, 45, F0, C7, 45, A4, 01, 00, 00, 00, 48, 89, 45, C0, 48, 8D, 05...
 
[+]

Entropy:
6.4237

Code size:
1.2 MB (1,281,536 bytes)

Scan osloadw8.exe - Powered by Reason Core Security